An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because exec.php has a popen call. NOTE: the vendor indicates that Merlin.PHP is designed only for use on a trusted intranet network, and intentionally allows remote code execution
Project Subscriptions
| Vendors | Products |
|---|---|
|
Asuswrt-merlin Project
Subscribe
|
Rt-ac1900
Subscribe
Rt-ac1900 Firmware
Subscribe
Rt-ac2900
Subscribe
Rt-ac2900 Firmware
Subscribe
Rt-ac3100
Subscribe
Rt-ac3100 Firmware
Subscribe
Rt-ac3200
Subscribe
Rt-ac3200 Firmware
Subscribe
Rt-ac5300
Subscribe
Rt-ac5300 Firmware
Subscribe
Rt-ac56u
Subscribe
Rt-ac56u Firmware
Subscribe
Rt-ac66u B1
Subscribe
Rt-ac66u B1 Firmware
Subscribe
Rt-ac68p
Subscribe
Rt-ac68p Firmware
Subscribe
Rt-ac68u
Subscribe
Rt-ac68u Firmware
Subscribe
Rt-ac68uf
Subscribe
Rt-ac68uf Firmware
Subscribe
Rt-ac86u
Subscribe
Rt-ac86u Firmware
Subscribe
Rt-ac87
Subscribe
Rt-ac87 Firmware
Subscribe
Rt-ac88u
Subscribe
Rt-ac88u Firmware
Subscribe
Rt Ac1900p
Subscribe
Rt Ac1900p Firmware
Subscribe
|
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T22:41:30.909Z
Reserved: 2018-10-15T00:00:00.000Z
Link: CVE-2018-18320
No data.
Status : Modified
Published: 2018-10-15T06:29:00.763
Modified: 2024-11-21T03:55:42.310
Link: CVE-2018-18320
No data.
OpenCVE Enrichment
No data.
Weaknesses